Privacy Notice
1. Who we are
PaperPlane is a marketplace project connecting creators, brands and independent creative professionals. Before public launch, the operator's legal name, registered address and official privacy/grievance contact must be inserted below.
Address: TODO: INSERT REGISTERED OR BUSINESS ADDRESS
Privacy & grievance contact: TODO: INSERT OFFICIAL CONTACT EMAIL
2. Data we collect
- Account data such as name/username, email, role and password credentials handled by Supabase Auth.
- Profile data you choose to publish, including bio, skills, rates, links, portfolio media and avatar.
- Marketplace activity such as gigs, applications, messages, saved gigs, reviews and reports.
- Security and operational logs needed to protect the service and investigate abuse.
We aim to collect only data reasonably needed for the service and stated purposes.
3. Purposes and legal basis
PaperPlane uses personal data to create and secure accounts, provide marketplace functionality, facilitate communications, prevent abuse, maintain records required by law, respond to support requests and improve reliability. Where consent is the basis for processing, it should be informed, specific and capable of withdrawal as provided by applicable law.
4. Public information
Profile information you choose to publish may be visible to other PaperPlane users. Do not publish private contact details, government identifiers, passwords, financial credentials or another person's personal information.
5. Children
PaperPlane currently restricts account registration to people aged 18 or older. We do not knowingly accept account registrations from children. The DPDP Act contains specific protections for children's personal data, including parental-consent requirements and restrictions on detrimental processing and tracking.
6. Your rights and requests
Subject to applicable law, you may request access to information about processing, correction/update, erasure where applicable, withdrawal of consent where consent is the legal basis, and grievance redressal. Contact TODO: INSERT OFFICIAL CONTACT EMAIL and include the account email and request type. We may need to verify identity before acting.
7. Security and breaches
PaperPlane uses Supabase Auth, database access controls, row-level security and server-side authorization. We will maintain reasonable technical and organisational safeguards and follow applicable breach-notification requirements. The 2025 DPDP Rules include security safeguards and breach-intimation requirements, with detailed provisions coming into force on the notified phased timeline.
8. Retention and deletion
We retain information only for as long as reasonably necessary for the stated purpose, user requests, security, dispute handling and legal obligations. Certain retention duties may apply under the DPDP Rules and other laws. We do not use the 3-year rule for large e-commerce entities as a blanket retention promise for a small platform; applicable thresholds and commencement dates matter.
9. Service providers and transfers
PaperPlane uses Supabase for authentication, database and storage infrastructure. Other service providers may be added only where needed. Cross-border processing or transfers will be handled subject to applicable Indian law and contractual/security requirements.
10. Contact
Privacy and data requests: TODO: INSERT OFFICIAL CONTACT EMAIL